Information System Security Manager (ISSM) - TS/SCI
AWS Cloud / RMF
Location: Arlington, VA - Onsite
Clearance Required: Active TS/SCI
Employment Type: Full-Time
ABOUT SBS
Strategic Business Systems, Inc. (SBS) delivers AWS-aligned mission-critical cloud, cybersecurity, software engineering, and data modernization solutions to the U.S. Department of Defense, Intelligence Community, and federal civilian agencies.
We hire engineers, architects, cybersecurity professionals, and consultants who want to perform hands-on work supporting high-impact national-security programs while collaborating directly with AWS Professional Services and Federal customers. Our culture is technical, lean, and clearance-focused, with an emphasis on professional development, certifications, and long-term customer engagements.
POSITION OVERVIEW
SBS is seeking an experienced Information System Security Manager (ISSM) to lead cybersecurity, Risk Management Framework (RMF), and authorization activities supporting Amazon Web Services (AWS) Federal customers operating within highly secure and classified cloud environments.
The ISSM will provide overall security leadership and governance for assigned information systems and cloud environments, ensuring compliance with DoD, Intelligence Community, NIST, and customer cybersecurity requirements. This individual will oversee the development and maintenance of Authorization to Operate (ATO) packages, continuous monitoring programs, vulnerability and risk management activities, and security control implementation across multiple security domains.
The ISSM will serve as a primary cybersecurity interface between customer security leadership, Authorizing Officials and their representatives, ISSOs, ISSEs, cloud engineers, architects, and program leadership.
The ideal candidate combines deep knowledge of RMF and NIST SP 800-53 with experience securing AWS cloud environments and has demonstrated the ability to lead systems through initial authorization and ongoing continuous monitoring.
RESPONSIBILITIES
Security Program Leadership
Risk Management Framework (RMF) & Authorization
Lead the complete RMF lifecycle in accordance with DoDI 8510.01, NIST SP 800-37, and NIST SP 800-53 Rev. 5.
Develop and manage strategies for obtaining and maintaining IATTs and ATOs.
Oversee development and maintenance of:
System Security Plans (SSPs)
Security Control Family Plans
Security Assessment documentation
Control Implementation Statements
Plans of Action & Milestones (POA&Ms)
Continuous Monitoring documentation
Risk assessments and authorization artifacts
Coordinate security control assessments and authorization reviews with customer security organizations and Authorizing Officials.
Track authorization conditions, findings, vulnerabilities, and POA&M items through closure.
Maintain system authorization packages within eMASS, Xacta, Keyhole, or equivalent GRC platforms.
AWS Cloud Security
Provide security oversight for AWS environments supporting IL2, IL4, Secret, and Top Secret workloads.
Assess AWS cloud architectures against applicable NIST and DoD security controls.
Partner with cloud architects and engineers to implement secure AWS architectures and services.
Provide oversight and guidance for AWS-native security capabilities including:
AWS Security Hub
Amazon GuardDuty
AWS Config
AWS Identity and Access Management (IAM)
AWS CloudTrail
AWS Organizations
Service Control Policies (SCPs)
AWS Key Management Service (KMS)
Review proposed architecture and system changes for cybersecurity and authorization impacts.
Support implementation of security controls within AWS Landing Zones and multi-account environments.
Continuous Monitoring & Vulnerability Management
Develop and oversee system Continuous Monitoring (ConMon) strategies.
Review vulnerability assessments, security scans, and compliance findings.
Establish priorities and timelines for vulnerability remediation based on mission and security risk.
Oversee POA&M development, management, and closure.
Coordinate remediation activities with engineering and operations teams.
Monitor security posture using AWS-native and third-party security platforms.
Support security tools and environments including:
ACAS
Palo Alto
Elastic
AWS Security Hub
AWS Config
GuardDuty
Ensure required vulnerability, configuration, and compliance reporting is completed accurately and on schedule.
Security Governance & Compliance
Ensure systems remain compliant with applicable:
DoD cybersecurity requirements
NIST SP 800-53
DISA STIGs
DoD Cloud Computing Security Requirements Guide (SRG)
Customer-specific security policies
Support cybersecurity inspections, audits, assessments, and authorization activities.
Identify security risks and provide mitigation recommendations to program and customer leadership.
Review significant system changes and determine potential impacts to system authorization.
Promote automation of security controls, evidence collection, compliance monitoring, and reporting where practical.
Collaboration
REQUIRED QUALIFICATIONS
PREFERRED QUALIFICATIONS
One or more of the following certifications is strongly preferred:
DESIRED SKILLS
Why SBS
SBS is a trusted technology and cybersecurity partner supporting federal agencies, the Department of Defense, Intelligence Community, and leading commercial technology companies.
Our ATOaaS offering is designed to solve a significant challenge for technology providers: navigating the complex security and authorization requirements necessary to bring commercial technologies into government environments.
You'll be part of a team that:
COMPENSATION & BENEFITS
SBS offers a comprehensive total-rewards package, including a market competitive salary along with:
Comprehensive medical, dental, and vision coverage; HSA-eligible plan options available
401(k) retirement plan with company match (vesting schedule per Plan Document)
Paid Time Off, federal holidays, and floating holiday for personal observance
Annual professional development support for AWS certifications, training, and conferences
Employee referral program where applicable and documented by program policy
Life, AD&D, and short- / long-term disability insurance
Telework and flexible-schedule support where mission and contract permit
Mission-focused federal contractor supporting national-security customers
Target Salary Range: $160,000-220,000. This range reflects the anticipated compensation for this role. Actual salary will be based on a combination of factors, including the position's scope and level of responsibility, the candidate's relevant experience, education, technical expertise, skills and qualifications, geographic location, and applicable business or contractual requirements.
Equal Employment Opportunity
SBS is an equal opportunity employer; all qualified applicants will receive consideration for employment without regard to age, gender, gender identity, sex, sexual orientation, color, race, creed, national origin, religion, marital status, parental status, citizenship status, ancestry, physical or mental disability, genetic information, veteran status, military status, or any other classification protected by federal, state, or local laws.
Accommodations
If you need an accommodation while seeking employment with SBS, please email hr@sbsplanet.com. Accommodations are made on a case-by-case basis.
No Unsolicited Agency Referrals
SBS does not accept unsolicited resumes from staffing agencies. Any resumes submitted without a prior agreement will be considered the property of SBS.
| Location | Arlington, VA |
| Industry | Computer/IT Services |
| Salary | $160,000–$220,000 Per Year |
| Company Size | 100 to 499 employees |
| Year Founded | 2000 |
| Website | http://www.sbsplanet.com/ |
Strategic Business Systems, Inc. (SBS) is an Information Technology (IT) Services Firm headquartered in the Washington, DC metropolitan area. Our expertise encompasses the full spectrum of infrastructure technologies including the latest network, server, storage, disaster recovery, security, and Internet technologies.
Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.
Free resume templatesImprove your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.
Free resume builder